SQL Injection Vulnerability in wpForo Forum Plugin for WordPress
CVE-2025-11740
6.5MEDIUM
What is CVE-2025-11740?
The wpForo Forum plugin for WordPress is susceptible to an SQL injection vulnerability due to inadequate escaping of user-supplied parameters and insufficient preparation in existing SQL queries. Authenticated attackers with Subscriber-level access or higher can exploit this flaw through the Subscriptions Manager. This allows them to inject additional SQL queries into existing ones, potentially resulting in unauthorized access to sensitive database information.
Affected Version(s)
wpForo Forum * <= 2.4.9